200H, very slow IPSec VPN remote access

Options
bbp
bbp Posts: 24  Freshman Member
First Anniversary 10 Comments Friend Collector First Answer

USG FLEX 200H, firmware V1.20(ABWV.0)

In theory, IKEv2 IPSec VPN should be faster, but on 200H it's only a third of throughput of SSL VPN. That's with AES256 and SHA256 for both phases.

If I increase SHA to 384 or even 512 and modp to 3072 it comes to a halt. Everything will time out.

It seems like hardware-accelerated encryption doesn't work as it should with IPSec VPN.